logo

GOFFEE continues to attack organizations in Russia

ID: 9bf7cc6b-be6e-5cc9-9c88-e396817b1acc

STIX ID: report--9bf7cc6b-be6e-5cc9-9c88-e396817b1acc

Feed Name: Securelist by Kaspersky

Threat Score
90/100

Date Published: 2025-04-10

Date Updated: 2026-04-29

Author: Oleg Kupreev

...
...

GOFFEE, a tracked APT, executed targeted spear‑phishing and removable‑media campaigns against Russian media, telecoms, construction, government and energy organizations (observed Jul–Dec 2024), deploying patched explorer.exe implants and multiple tools including a PowerShell downloader (PowerModul), a PowerShell Mythic agent (PowerTaskel), a binary Mythic agent, FlashFileGrabber (data-stealer), and a USB Worm; the report provides technical TTPs for initial access, persistence, lateral movement (PsExec/WinRM), and includes IoCs (file hashes, C2 IPs) and detailed payload behavior.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.